Data Processing Agreement
What this is
This is the agreement Article 28 of the GDPR requires between a controller and a processor. It forms part of the Terms of Service and takes effect when you accept them.
You are the controller of your clients' data — you decide whose details are held and why. Anda Tech Solutions S.R.L. ('we', 'us', 'TendMate') is the processor — we hold and handle that data only to give you the service.
Anda Tech Solutions S.R.L., a company registered in Romania under trade-register number J40/10329/2022, tax identification code (CUI) 46223108, with its registered office at Strada Economu Cezărescu 52, Bloc 1, Etaj 5, Ap. 1509, Sector 6, Bucharest, Romania. You can reach us at contact@tendmatehq.com.
If you are established outside the EU or UK, you do not become subject to the GDPR by using an EU processor. This agreement still binds us, and it describes what we owe you either way.
1. We act only on your instructions
We process your clients' data only to provide TendMate, and only as you instruct — through your use of the product, through the configuration we author with you, and through any written instruction you give us. We do not use it for our own purposes, we do not sell it, and we do not train anything on it.
If an instruction of yours appears to us to breach data protection law, we will tell you immediately and may pause that instruction until it is resolved.
We will only transfer this data outside the EEA where a lawful transfer mechanism is in place, as described in section 6.
2. Confidentiality
Everyone we allow near your data is bound to confidentiality, and access is limited to those who need it to run or support the service.
An operator of ours can open a read-only view of your account to help you. Every such session is logged — who, when, for how long, and what they were looking at — and there is no way for an operator to change your data through it. Operators cannot agree to these documents on your behalf.
3. Security (Article 32)
The measures in place today:
- All traffic encrypted in transit; the database encrypted at rest by the hosting provider.
- Door and alarm codes are encrypted individually, with a key held by the application and never stored in the database. Someone who obtained a copy of the database — a stolen backup, a mislaid export — would not be able to read them.
- Sign-in is by emailed one-time link. There are no passwords to leak, links expire in fifteen minutes, are single-use, and only a hash of each is stored.
- The helper's restrictions are enforced on the server, not in the interface: rates, prices and expenses are removed from the data before it ever reaches her device, and an automated test reads the raw network response on every build to prove it.
- Each business's data is separated at every query, and cross-business access is covered by automated tests.
- Backups.
Two limits of that encryption, stated plainly because you are entitled to know them. The helper you authorise is shown the code, because she has to open the door — encryption protects the stored copy, not the person you gave access to. And the key is held by us, which is what lets her phone show the code when it has no signal; we could therefore read a code if we chose to, and section 2 is what governs when anybody here may.
Free-text notes are not encrypted this way, and they are the field most likely to end up holding something you would rather it did not. Please keep that in mind when writing them.
4. Sub-processors
You give us general written authorisation to engage the sub-processors below. Each is bound by a contract with obligations no weaker than these.
- Railway Corp. — application and database hosting. Services and database are pinned to the Amsterdam (europe-west4) region, which a test asserts on every build.
- Resend (Plus Five Five, Inc.) — transactional email only: sign-in links and worker invitations. Stores data in the United States; certified under the EU-US Data Privacy Framework and covered by Standard Contractual Clauses.
- Stripe, Inc. — subscription billing. Engaged only once billing is live; it never receives your clients' data, only your own billing identifiers.
We will give you reasonable notice before adding or replacing one. If you object on reasonable data-protection grounds, you may end your subscription and take your data with you.
5. Helping you with your own duties
If one of your clients asks you for their data, or asks you to correct or delete it, the product answers most of that directly: you can export everything in one click, and edit or delete any record yourself. Where you need more than that, we will help you, taking into account the nature of the processing.
We will also give you reasonable help with data protection impact assessments and with any prior consultation you have to make.
We will tell you without undue delay after becoming aware of a personal data breach affecting your data, with what we know at the time, and keep you updated as we learn more.
6. International transfers
The application and database are in the Netherlands. The one routine transfer outside the EEA is transactional email, sent through a US provider certified under the EU-US Data Privacy Framework and additionally covered by the Standard Contractual Clauses in its own agreement with us.
Your clients' names, addresses and codes are not sent through that provider. What reaches it is a recipient's email address and the text of a sign-in or invitation message.
7. Deletion and return
You can export everything at any time, without asking us.
When your subscription ends, your data stays readable and downloadable for thirty days. After that we delete it on your instruction, and otherwise on our ordinary schedule.
Two honest limits. Deleted records are first marked deleted and removed later rather than instantly, so that a deletion made offline by one device cannot be resurrected by another. And backups holding your data are overwritten on their own rotation, so erasure reaches them when that rotation completes rather than at the moment you ask.
8. Audit
We will make available the information you reasonably need to show that we are meeting these obligations, and we will contribute to an audit you or your auditor conducts, on reasonable notice and no more than once a year unless a supervisory authority or an incident requires otherwise.
Annex — what is processed
Subject matter. Providing the TendMate scheduling service to you.
Duration. For as long as your subscription lasts, plus the thirty-day window afterwards.
Nature and purpose. Storing, organising, displaying and synchronising your business records so that your visits are scheduled and nobody is missed; making them available to you and to the helpers you authorise; and producing exports at your request.
Categories of data subject. Your clients; the people at properties you look after; and, where you record them, guests staying at those properties.
Types of personal data.
- Names, telephone numbers, email addresses and property addresses of your clients.
- Details of the property: bedrooms, bathrooms, size, expected hours.
- Access codes for alarms, doors and gates, where you record them.
- Free-text notes you write about a client or a visit.
- Dates, service types and status of visits, and the rates and prices you set.
- Where you use occupancy tracking: dates a property is occupied, and — only if you enter them — a guest's name, phone number, notes and your rating of them.
Special categories. None are asked for. Free-text notes can contain anything you write there, including things the law treats as sensitive; please keep that in mind when writing them.